IDOR - Delete all Licenses and certifications from users account using CreateOrUpdateHackerCertification GraphQL query

Program: hackerone Bug Type: IDOR Bounty: 12500 Date: 2023-08-24
IDOR sensitive-data

Summary

A Researcher found a vulnerability in a graphql endpoint that allows a attacker to delete Licenses and Certifications stored in the profile with guessable ID. A range of data - licenses and certifications can also be deleted by specifying a range value with the guessable ID.

References